Managed Detection & Response (MDR)
Service description
Managed Detection and Response (MDR) is a cybersecurity service that provides organizations with 24/7 threat monitoring, detection, investigation, and response capabilities, often using a combination of advanced technology and human expertise. It's an outsourced solution that helps organizations enhance their security posture and reduce the risk of breaches by leveraging security operations center (SOC)-like functions.
Common industries
Applies to any business with systems to protect, especially those without an in-house security team.
ROI
Continuous coverage detects and contains threats fast, lowering breach likelihood and cost — usually cheaper than staffing an in-house SOC.
Benefit
(i) Improved Security Posture: MDR helps organizations strengthen their overall security posture by proactively identifying and addressing threats. (ii) Reduced Time to Detect and Respond: MDR can significantly reduce the time it takes to detect and respond to security incidents, minimizing potential damage. (iii) Expertise and Resources: MDR provides access to a team of security experts and advanced technologies that many organizations may not have in-house. (iv) Focus on Core Business: By outsourcing security operations, organizations can focus on their core business activities. (v) Cost-Effective: MDR can be a more cost-effective solution than building and maintaining an in-house SOC, especially for smaller or resource-constrained organizations.
Why get it
Attacks can start at any hour and spread fast. Round-the-clock monitoring and expert response helps contain an attack early, which a small team often cannot staff.
When you benefit
Onboarding first, then continuous 24/7 monitoring under a recurring contract.
What it costs
Typically a monthly fee.
When you pay
Providers usually charge a monthly fee per device, user or data volume, with a setup fee in some cases. Response work beyond what the contract includes, such as a major incident investigation, is often billed separately.
Other costs
Endpoint or logging software the provider requires, licenses for any existing tools, and staff time for onboarding.
Risks to know
The provider sees sensitive systems and communications, so its monitoring must be authorized in the contract. Federal law restricts intercepting communications, with exceptions that include consent and a provider protecting its own service. Some businesses must also report incidents to government agencies, and the provider is itself a path into the business if breached.
When risks arise
Monitoring gaps often show up only during an incident. Reporting duties run from when an incident is discovered or reasonably believed to have occurred, so the clock starts quickly.
The process
The provider deploys monitoring tools and tunes them to the business's systems. It watches for threats continuously, investigates alerts and acts or advises on response under the agreed rules. The business receives incident reports and periodic summaries, and fixes root causes with the provider's guidance.
Your commitment
The business gives the provider access to endpoints, logs and cloud accounts, and names who the provider calls at any hour. It should agree in writing what the provider may do on its own during an attack, such as isolating a device.
Documents to gather
- List of endpoints, servers and cloud accounts
- Network diagram
- Existing incident response plan
- Contacts and escalation list
Helpful reading
- Building a Security Operations Centre (SOC) — National Cyber Security Centre (UK)
- SP 800-61 Rev. 3, Incident Response Recommendations and Considerations for Cybersecurity Risk Management — NIST
- Stop Ransomware — CISA
Further research
- 18 U.S. Code § 2511 — Interception and disclosure of wire, oral, or electronic communications prohibited (federal)
- 18 U.S. Code § 2701 — Unlawful access to stored communications (federal)
- 6 U.S. Code § 681b — Required reporting of certain cyber incidents (CIRCIA, federal)
- CISA — Cyber Incident Reporting for Critical Infrastructure Act of 2022 (CIRCIA), including final-rule status
- Regulation (EU) 2016/679 (GDPR), Articles 28 and 32 — processors and security of processing (European Union)
Not open yet
Managed Detection & Response (MDR) isn’t taking requests yet. Join the waitlist. It is listed in your requests tray.